Skip to main content

Security Reporting in SpartanX: Generate Professional Reports Fast

Choose from 84 report templates covering PCI DSS, HIPAA, SOC 2, and more. Customize tone and audience via AI, then export as PDF, Markdown, or Google Docs.

Written by SpartanX CS

SpartanX includes a powerful reporting engine capable of generating 84 different report types, from technical penetration test summaries to compliance-mapped reports for frameworks like PCI DSS, HIPAA, SOC 2, and Cyber Essentials. Reports are fully interactive — you can refine them, adjust the presentation, and export in multiple formats.


Generating a Report from an Engagement

The simplest way to generate a report is directly from a completed engagement. Click "Reports" within the engagement view — the collection is pre-filled and the vulnerability data is scoped to that engagement automatically.

Select the report type from the available 84 options. Examples include:

  • PCI DSS — maps vulnerability findings to PCI requirements

  • HIPAA — compliance-focused report for healthcare organizations

  • High Trust — for healthcare industry assurance programs

  • Cyber Essentials — for UK organizations

  • SOC 2 — for service organizations

After selecting the report type, specify the assets in scope (e.g., the cardholder environment for PCI), choose the reporting language, and click Run. Report generation takes a few minutes and runs on a dedicated back-end service.


Generating Reports from the Reports Tab

The standalone Reports tab allows you to generate reports without starting from an engagement. From here, you manually select:

  • The collection to report on

  • The specific assets in scope

  • The report type and reporting language

This is useful when you want to produce a report covering multiple engagements within the same collection, or when the report consumer is different from the engagement owner.


Reviewing and Refining Reports

Once generated, you can connect to the agent flow to see exactly how the report was built — a step-by-step breakdown of the executive summary and artifact creation process.

Reports are interactive. You can request modifications such as:

  • Making the report more developer-friendly (adding code snippets, technical detail)

  • Simplifying it to an executive-level summary for risk and compliance managers

  • Adding tables, charts, or additional context for specific audiences like firewall engineers

One important constraint: you cannot modify the underlying vulnerability data through the report interface. SpartanX is the source of truth for findings, and report customization only affects presentation.


Exporting Reports

Completed reports can be exported as:

  • Markdown — for integration with documentation systems or further processing

  • PDF — for sharing with stakeholders, auditors, or regulators

  • Google Docs (coming soon) — for direct integration with Google Drive

If your organization needs a report type not currently in the 84 available options — such as regional compliance reports for specific markets — the SpartanX team can add these quickly.


What's Next

The next section covers Organizational Policies — a unique SpartanX feature that brings your internal policy documents into the platform, enabling automated policy violation detection during engagements.

Did this answer your question?